Public Compliance Resources for Shipping LLM Apps: EU AI Act, GDPR, CNIL and EDPB Guidance

felix_baron · reddit · 2026-09-23

A Reddit user compiled public resources engineering, legal, and security teams need before launching an LLM app: the EU AI Act and GDPR texts; the EU AI Act Service Desk compliance checker; German DSK guidance on AI/data protection and RAG-specific privacy; French CNIL AI how-to sheets and its open-source PIA impact-assessment software; EDPB's privacy-by-design guidelines and Opinion 28/2024 on AI models; German BSI's generative AI risk guidance; and the EU GPAI Code of Practice (which applies to model providers, not every app).

They stress distinguishing technical recommendations, regulator interpretations, and legal obligations, and propose a tax-software-style guided review where each card shows the decision, applicable source, implementation evidence, and reviewer's ruling. The post closes by asking how other teams actually run such reviews.

Original post →

More from Safety

Safety channel →